Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-10842
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could …
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-15435
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
HIGH 8.8
CVE-2026-14980
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to per…
Websphere Application Server
26.0.0.9+
CRITICAL 9.8
CVE-2026-14522
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
HIGH 7.5
CVE-2026-14519
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a …
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
CRITICAL 9.3
CVE-2026-11707
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the …
Websphere Application Server
Mitigation only
HIGH 7.5
CVE-2026-11897
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted requ…
Websphere Application Server
26.0.0.8+
HIGH 7.5
CVE-2026-12947
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that coul…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
HIGH 7.3
CVE-2026-11980
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
Aspera
after 1.0.19
MEDIUM 5.4
CVE-2025-36431
IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. …
Sterling B2b Integrator
No fix yet
MEDIUM 5.4
CVE-2026-11383
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative C…
Websphere Application Server
No fix yet
MEDIUM 5.4
CVE-2025-36298
IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM St…
Sterling B2b Integrator
No fix yet
HIGH 8.8
CVE-2026-2482
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to exe…
Websphere Application Server
26.0.0.9+
CRITICAL 9.8
CVE-2026-14529
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
HIGH 8.7
CVE-2026-15064
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
HIGH 8.7
CVE-2026-15325
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of T…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
HIGH 8.2
CVE-2026-14996
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
Aspera Faspex
5.0.16+
HIGH 8.1
CVE-2026-15328
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request …
Websphere Application Server
8.5.5.31 / 9.0.5.29+
HIGH 7.5
CVE-2026-14981
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
HIGH 7.5
CVE-2026-15057
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
Websphere Application Server
26.0.0.8+
HIGH 7.5
CVE-2026-15280
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i…
Websphere Application Server
26.0.0.9+
CRITICAL 9.8
CVE-2026-14974
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
CRITICAL 9.8
CVE-2026-14976
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…
Websphere Application Server
26.0.0.9+
CRITICAL 9.3
CVE-2026-14973
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
Aspera
after 1.0.19
HIGH 7.5
CVE-2026-14528
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
Websphere Application Server
8.5.5.31 / 9.0.5.29+
HIGH 7.2
CVE-2026-14958
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Aspera Faspex
5.0.16+
HIGH 7.2
CVE-2026-14959
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Aspera Faspex
5.0.16+
CRITICAL 9.8
CVE-2026-14446
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Websphere Application Server
8.5.5.30 / 9.0.5.28+
CRITICAL 9.8
CVE-2026-14512
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
MEDIUM 6.1
CVE-2026-14515
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
Websphere Application Server
8.5.5.31 / 9.0.5.29+